7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37171
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality.

CVE-2020-6070
F2fs-tools General
6.7
MEDIUM
EPSS
0.6%
2020 1 PoC

An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-37109
aSc TimeTables General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an application crash and potential instability.

CVE-2020-37164
AbsoluteTelnet General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.

CVE-2020-14344
libX11 General
6.7
MEDIUM
EPSS
0.2%
2020 CWE-190 1 PoC

An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.

CVE-2020-36943
asc Timetables General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields with excessive data. Attackers can generate a 10,000-character buffer and paste it into the subject title to trigger application instability and potential crash.

CVE-2020-37131
Product Key Explorer General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.

CVE-2020-37181
Torrent FLV Converter Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-121 1 PoC

Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite techniques to potentially execute arbitrary code on vulnerable Windows 32-bit systems.

CVE-2020-14386
kernel General
6.7
MEDIUM
EPSS
0.6%
2020 CWE-787 4 PoCs

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-36694
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2020 2 PoCs

An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.

CVE-2020-37192
MSN Password Recovery General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-611 1 PoC

MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

CVE-2020-37136
ZOC Terminal Networking
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files.

CVE-2020-37133
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.

CVE-2020-7305
DLP ePO extension General
6.7
MEDIUM
EPSS
0.2%
2020 CWE-269 1 PoC

Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

CVE-2020-37165
AbsoluteTelnet General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash.

CVE-2020-37132
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

CVE-2020-7320
Endpoint Security for Windows Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-693 1 PoC

Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.

CVE-2020-15145
windows-setup Web Windows
6.7
MEDIUM
EPSS
0.0%
2020 CWE-276 2 PoCs

In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when composer is run by an administrator. 2. A local regular user may create a specially crafted dll in the `C:\ProgramData\ComposerSetup\bin` folder in order to get Local System privileges. See: https://itm4n.github.io/windows-server-netman-dll-hijacking. 3. If the directory of the php.

CVE-2020-37177
BOOTP Turbo General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.

CVE-2020-37130
Nsauditor General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.